Application of ISO 27002 Controls on Data Privacy for Risk Prevention: Rumiñahui Educational Unit Case
摘要
The main objective of this document is to evaluate the controls of the ISO 27002 Standard on data privacy and to identify risks considered critical through ISO 27005 in the IT area of the Rumiñahui Educational Unit. That is why to meet the objectives, the methodology proposed by Kitchenham & Charters is used, in which guidelines are given for systemic literature reviews in software engineering; It is considered descriptive research with a mixed approach; The research techniques are direct observation for contact with the object of study, documentary review of standards and good practices; Action Research is considered as a methodology; without requiring sampling since the study population corresponds to the IT area. The main results showed that there is a greater risk of threats related to information compromise, at the level of data, networks and human factor, in addition to 49 of the ISO 27002 controls, equivalent to 41%, that are not being met, in as opposed to 5% which, if they have been fully fulfilled, so a general analysis can be carried out where it is concluded that 88% are partially fulfilled. It is concluded that it is important to take corrective actions to avoid the loss of information; as well as implement good practices.